A security release. It resolves both open advisories in full and the
release-blocking findings from the 2026-09-30 source audits. No .ai-jail
config field or CLI flag changed; a couple of behaviours now fail closed where
they previously degraded silently (noted below).
Security
Closes GHSA-w976-gw52-hvx2 (five findings) and GHSA-frgp-q3qc-g78p.
-
Worktree metadata can no longer bind an arbitrary host directory
read-write.--worktreevalidation now requires the linked-worktree layout
to be genuine — the per-worktree git dir must be<commondir>/worktrees/<name>
with both paths canonicalized — instead of trusting a repository-authored
commondirfile to name any existing directory. (advisory #1) -
Duplicate environment entries no longer defeat phantom-secret injection.
--secretnow resolves a bound key with the same last-wins precedence the
child environment uses, removes every entry for that key, and inserts one
placeholder. Previously a laterKEY=realentry (e.g. a credential file plus
--env KEY) delivered the real value into the sandbox. -
A browser command from an untrusted project can no longer clear a trusted
lockdown. The browser profile only clears lockdown when the browser was
chosen by trusted input (an explicit--browser/global profile, or a command
on the CLI or from a trusted layer). Acommand = ["chromium"]in a cloned
repo's.ai-jailkeeps lockdown; run the browser from the CLI to open a
window. (advisory #3) -
TIOCSTI is filtered as the kernel reads it. The seccomp rule now compares
the ioctl request as a 32-bit value, closing a bypass where
TIOCSTI | (1 << 32)slipped past a 64-bit comparison and still reached the
same terminal-injection ioctl. (advisory #2) -
Landlock now scopes abstract Unix sockets and signals (ABI V6,
best-effort). This is the backstop the threat model documented but did not
apply: without it,--x11/--networkleft the host's abstract X11 socket
reachable and--systemd-userleft host signalling open. Kernels below V6
(< 6.12) keep the existing filesystem (V3) and network (V4) enforcement
unchanged. (advisory GHSA-frgp-q3qc-g78p) -
macOS: terminal read/write is scoped to this run's own terminals — the
allocated PTY and the caller's own/dev/tty— not a blanket/dev/ttys*
grant, so a sandboxed process cannot open another of your terminals by path
and write escape sequences to it. (advisory #4) -
macOS:
--masked project paths are denied for writes as well as reads, so
a file the agent cannot read cannot be blindly overwritten through the project
write allowance either. (advisory #5) -
The primary-screen escape filter no longer collapses on a doubled
introducer. A freshESCnow aborts any partial sequence and is never
forwarded, soESC ESC ]52;…andESC [ ESC ]…— which terminals collapse
into a single introducer — can no longer smuggle an OSC (e.g. a clipboard
write) past the filter. -
The proxy's test-only escape hatches are gone from release builds.
AI_JAIL_TEST_PROXY_ALLOW_PRIVATE(SSRF guard off) and
AI_JAIL_TEST_PROXY_EXTRA_ROOTS(extra TLS root) are now compiled in only
under thetest-hooksfeature; a release build andcargo installcontain
neither the env-var reads nor their strings, so the environment is no longer a
control channel over them.
Changed (fail closed)
- Overlay setup failures now abort the launch. A missing overlay source, an
overlapping destination, or a storage-creation failure previously warned and
continued with the plain read-write project bind — silently modifying the real
files a user expected copy-on-write to protect. Overlay storage directories are
also now collision-resistant (hashed from the canonical destination).
Testing
- New regression tests for each fix, including runtime seccomp coverage of the
TIOCSTI high-bit bypass. The filtered-egress and phantom-secret end-to-end
suites now require--features test-hooks(which enables the hatches above);
CI runs the suite with that feature, and the files are gated so a plain
cargo testskips rather than fails them.
Checksums (SHA256)
86a92e4524284fb7210c887655253b98e5a9349699d23c60448fde4336a89ed0 ai-jail-linux-x86_64.tar.gz
74b94c716b8e73080824397c99079ca27e4c88f3713bbc8f9954a527d66d2da1 ai-jail-macos-aarch64.tar.gz
Install
brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail